¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180920
°ä²¼¹¦·ò 2018-09-20¡¾·ÖÎö»ã±¨¡¿Å·ÖÞÐ̾¯×éÖ¯°ä²¼2018Ä껥ÁªÍøÓÐ×éÖ¯·¸×ïÍþвÆÀ¹À»ã±¨
Å·ÖÞÐ̾¯×éÖ¯Â½ÐøµÚÎåÄê°ä²¼»¥ÁªÍøÓÐ×éÖ¯·¸×ïÍþвÆÀ¹À»ã±¨£¨IOCTA2018°æ£©£¬»ã±¨ÖÐÈ«Ãæ¸ÅÊöÁ˵±Ç°ÒÔ¼°½«À´µÄ·¸×ïÍþвºÍÇ÷Ïò¡£ÆäÖØÒª·¢ÏÖÔ̺¬£ºÀÕË÷Èí¼þÈÔά³ÖÖ÷µ¼Ö°Î»£»·¸×ï·Ö×Ó³ÖÐøÀûÓÃDDoS¹¥»÷Õë¶Ô¸öÈËÆóÒµºÍ¹«¹²ÐÐÒµ£»¶ùͯÐÔ°þÏ÷×ÊÁϵÄÊýÁ¿³ÖÐøÔö³¤£»ÎÞ¿¨Ö§¸¶Ú²Æ³ÉΪÖ÷Á÷£¬µ«skimmerÈÔÔÚ³ÖÐø·¢Õ¹£»Õë¶Ô¼ÓÃÜÇ®±Ò³ÖÓÐÕߺÍÂòÂôËùµÄ·¸×ï»î¶¯ÉÏÉý£»¶ñÒâÍÚ¿ó³ÉΪ³±Ë®£»Éç½»¹¤³ÌÒÀÈ»ÊdzÁÒªµÄ¹¥»÷ÏòÁ¿£»ÖØÒªµÄ°µÍøÊг¡±»¹Ø¹Ø£¬µ«ÒµÎñ»¹ÔÚ½øÐС£
https://www.europol.europa.eu/internet-organised-crime-threat-assessment-2018
¡¾·ÖÎö»ã±¨¡¿Akamai°ä²¼2018Ä껥ÁªÍø°²È«Çé¿ö»ã±¨£¬³Áµã¹Ø×¢Í´´¦Ìî³ä¹¥»÷
Akamai°ä²¼2018Ä껥ÁªÍø°²È«Çé¿ö»ã±¨£¬³Áµã¹Ø×¢½ðÈÚÐÐÒµÃæ¶ÔµÄй¥»÷Ç÷Ïò - Í´´¦Ìî³ä¹¥»÷¡£2018Äê5ÔÂÖÁ6ÔÂÆÚ¼äAkamaiÔÚÆäÖÇÄÜÆ½Ì¨ÉϹ²¼ì²âµ½³¬¹ý83ÒڴζñÒâµÇ¼³¢ÊÔ¡£»ã±¨·ÖÎöÁ˽©Ê¬ÍøÂçµÄ×îÐÂÕ½ÊõºÍÇ÷Ïò£¬Ô̺¬Ö¸±êÐÐÒµºÍ¹ú¶È£¬²¢Éî¿Ì×êÑÐÁËÒ»¸öÕë¶ÔÁ½¸ö½ðÈÚ»ú¹¹µÄ¶à½©Ê¬ÍøÂç¡¢³¤¹¦·òµÄÍ´´¦Ìî³ä¹¥»÷¡£»ã±¨Öл¹·ÖÎöÁËÍ´´¦Ìî³ä¹¥»÷Ôö³¤µÄÔÒòÒÔ¼°×éÖ¯¸Ä½øÆä·À»¤´ëÊ©µÄ±ØÒªÐÔ¡£
https://www.akamai.com/us/en/about/our-thinking/state-of-the-internet-report/global-state-of-the-internet-security-ddos-attack-reports.jsp
¡¾¹¥»÷ÊÂÎñ¡¿ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶
ÃÀ¹ú¹úÎñÔºµÄµç×ÓÓʼþϵͳÔâµ½ºÚ¿Í¹¥»÷£¬ÉÙÊýÔ±¹¤£¨²»µ½1%£©µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜй¶¡£Æ¾¾Ý¹úÎñÔº°ä²¼µÄ²¼¸æ£¬¸Ãµç×ÓÓʼþϵͳ³¤¶Ì»úÃÜÐÔµç×ÓÓʼþϵͳ£¬Æä±»ÃèÊöΪÃô¸Ðµ«²»Éæ¼°»úÃÜ¡£¹úÎñÔº½²»°ÈËNicole Thompson°µÊ¾ÕâÒ»ÊÂÎñ»¹ÔÚµ÷²éÖ®ÖУ¬¹úÎñÔºÔÚÓëºÏ×÷ͬ°éºÍ˽Ӫ²¿ÃÅ·þÎñÉ̹²Í¬½øÐÐÈ«ÃæµÄÆÀ¹À¡£
https://www.politico.com/story/2018/09/17/state-department-email-personal-information-792665
¡¾¹¥»÷ÊÂÎñ¡¿·ÆÂɱö¹ã²¥¹«Ë¾ABS-CBNÔâºÚ¿Í¹¥»÷£¬²¿Ãſͻ§µÄ²ÆÕþÊý¾ÝÒɱ»ÇÔ
·ÆÂɱö¹ã²¥¹«Ë¾ABS-CBNµÄÔÚÏßÉ̵êϰȾMagecart¶ñÒâ¾ç±¾£¬²¿Ãſͻ§µÄÖ§¸¶ÐÅÏ¢ÒÉй¶¡£Æ¾¾ÝºÉÀ¼°²È«×êÑÐÈËÔ±Willem GrootµÄ˵·¨£¬¸Ã¶ñÒâ¾ç±¾×Ô2018Äê8ÔÂÒÔÀ´Ò»Ïò»îÔ¾¡£ABS-CBNÊÇ·ÆÂɱö×î´óµÄÓÐÏßµçÊÓ·þÎñÉÌ¡£ÕâЩ±»À¹½ØµÄÓû§²ÆÕþÊý¾Ý±»·¢Ë͵½×¢²áְλÓÚ¶íÂÞ˹ÒÁ¶û¿â´Ä¿ËµÄ·þÎñÆ÷¡£Ä¿Ç°»¹²»Ã÷ÏÔÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£
https://www.zdnet.com/article/broadcasting-giant-abs-cbn-customer-data-stolen-sent-to-russian-servers/
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±Åû¶Î÷ÊýMy Cloud NASÉ豸ÖеÄÒ»¸öÉÐ佨¸´µÄ°²È«·ì϶
SecurifyµÄ×êÑÐÈËÔ±Åû¶Î÷²¿Êý¾ÝµÄMy Cloud NASÉ豸ÖеÄÒ»¸öÉÐ佨¸´µÄ°²È«·ì϶¡£¸Ã·ì϶£¨CVE-2018-17153£©¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÌáȨÖÁÖÎÀíԱȨÏÞ£¬²¢»ñµÃ¶ÔÊÜÓ°ÏìNASÉ豸µÄÆëÈ«½ÚÔ죬ÒÔ¼°Äܹ»²é¿´¡¢¸´Ô졢ɾ³ýºÍ¸²¸ÇÉ豸ÉϵÄÈκÎÎļþ¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÓйØPoC¡£¸Ã·ìÏ¶ÔøÓÚ2017Äê4Ô»㱨¸øÎ÷²¿Êý¾Ý£¬µ«¸Ã¹«Ë¾ÖÁ½ñûÓнøÐÐÈκλظ´ºÍ½¨¸´¡£
https://thehackernews.com/2018/09/wd-my-cloud-nas-hacking.html
¡¾·ì϶²¹¶¡¡¿Ë¼¿Æ°ä²¼WebexÍøÂç¼Ôì²¥·ÅÆ÷µÄ°²È«¸üУ¬½¨¸´¶à¸ö·ì϶
˼¿Æ½¨¸´ÁËWebexÍøÂç¼Ôì²¥·ÅÆ÷ÖеĶà¸ö°²È«·ì϶¡£ÕâЩ·ì϶ÊÇÓÉÓÚWebex¼ÔìÎļþµÄ²»ÕýÈ·ÑéÖ¤µ¼Öµģ¬¹¥»÷Õß¿ÉÄÜͨ¹ý´¹µöÁ´½Ó»ò´¹µöÓʼþÓÕʹÓû§´ò¿ª¶ñÒâµÄARFÎļþ´¥·¢ÕâЩ·ì϶£¬µ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¸ÃÈí¼þµÄWindows¡¢OS XºÍLinux°æ±¾¶¼Êܵ½Ó°Ï죬½¨ÒéÓû§¾¡¿ì½øÐиüС£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180919-webex


¾©¹«Íø°²±¸11010802024551ºÅ